ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-31251
+3 in the same advisory: …31249 …31252 …31250
An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privilege

An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.

NVD description · AI analysis pending
9.8
group max
36% PoC ×2
  • chiyu-tech bf-430 firmware
  • chiyu-tech bf-431 firmware
  • chiyu-tech bf-450m firmware
  • +1 more
CVE-2021-31643
An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization o

An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter.

NVD description · AI analysis pending
5.488% PoC ×3
  • chiyu-tech bf-631 firmware
  • chiyu-tech bf-630 firmware
  • chiyu-tech semac s2 firmware
  • +1 more
CVE-2021-31642
A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, an

A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.

NVD description · AI analysis pending
6.544% PoC ×3
  • chiyu-tech semac s2 firmware
  • chiyu-tech semac d1 firmware
  • chiyu-tech semac d2 firmware
  • +1 more
CVE-2021-31641
An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass,

An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated.

NVD description · AI analysis pending
6.15% PoC ×3
  • chiyu-tech bf-430 firmware
  • chiyu-tech bf-431 firmware
  • chiyu-tech bf-450m firmware
  • +1 more